2026-07-08
Population: stories the tracker first saw on this Coordinated Universal Time (UTC) calendar day; publisher date is used only if first-tracked time is unavailable and remains on each item.
- government policy
Mexico's New Cyber Plan Faces Its First Real Test
Mexico is testing its newly developed cybersecurity plan during the FIFA World Cup, which represents an early operational challenge for the initiative still in its expansion phase. The plan must demonstrate its effectiveness during the high-profile event as a real-world validation of its defensive capabilities.
Why it matters: Security practitioners in Mexico and organizations supporting the World Cup need to understand whether the national cyber defense infrastructure can withstand coordinated attacks or disruptions targeting critical event infrastructure, sporting facilities, and government systems.
- breaches incidents
Mount Royal University confirms breach as hackers claim attack
Mount Royal University in Calgary confirmed a network breach in which attackers stole data from file storage systems before deleting it. The university is investigating the incident and working to restore affected systems.
Why it matters: Higher education staff and students at Mount Royal need to monitor for credential compromise and potential misuse of stolen data, and should follow institutional guidance on password changes and monitoring accounts.
- cloud saas
Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
A single threat actor compromised an Amazon Web Services (AWS) cloud environment by leveraging artificial intelligence (AI) workflows, chaining cloud misconfigurations, and using stolen credentials. The intrusion led to extortion against a major AWS customer within 72 hours.
Why it matters: AWS customers with exposed AI workflows or weak credential hygiene face immediate risk of targeted extortion attacks.
- threat intel
Greek victims file lawsuit against Intellexa over Predator spyware
Greek citizens whose phones were infected with Predator spyware have filed a lawsuit against Intellexa, the company behind the surveillance tool. The infections were discovered in 2022 and sparked a major political scandal that resulted in the resignation of Greece's intelligence chief and the prime minister's chief of staff.
Why it matters: Greek nationals affected by targeted spyware deployment should understand their legal remedies and timeline for claims; security leaders should monitor how courts handle commercial spyware liability and jurisdictional accountability.
- regulatory
Cash App owner to pay $45 million to settle allegations of lax security
Block, Inc., owner of Cash App, has agreed to pay $45 million to settle allegations from state attorneys general that it misrepresented the security protections offered to users. The settlement addresses claims that the company falsely promised Cash App users would receive bank-equivalent security safeguards.
Why it matters: Payment processors and fintech companies need to review their security claims and disclosures to avoid similar enforcement actions; organizations should ensure marketing materials accurately reflect the actual security controls in place.
- threat intel
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Malicious packages impersonating software development kits (SDKs) for Paysafe, Skrill, and Neteller payment services were distributed via npm and PyPI. The packages contained stealer malware designed to exfiltrate credentials from developers and application users.
Why it matters: Developers who installed these fake SDKs face credential compromise and potential account takeover; practitioners should audit npm and PyPI dependencies for these impostor packages and revoke any exposed credentials immediately.
- breaches incidents
Uniondale Union Free School District - Audit Follow-Up by New York State Comptroller (2023M-61-F)
New York State Comptroller released an IT audit of Uniondale Union Free School District in October 2023 that examined management of non-student user network controls. The audit found that district officials did not adequately manage non-student network user accounts and permissions.
Why it matters: School IT administrators and district security teams should review their own user access controls and account management practices to identify similar gaps in non-student account oversight and remediate before audits occur.
- ai security
French nonprofit starts global intelligence and research hub for AI cyber threats
The Paris Peace Forum has launched INTAiC, a global initiative to assess artificial intelligence (AI) cyber threats and coordinate international responses. The network will operate two workstreams: one to provide defenders with current threat intelligence on how AI reshapes cyber attacks, and another to evaluate and prevent AI-related cyber risks through independent expert assessments. The effort aims to consolidate fragmented threat data from network defenders and AI security specialists into a unified resource for policymakers and organizations.
Why it matters: Security practitioners and policymakers need to engage with this coordinated intelligence effort because AI-driven threats are fragmenting across separate communities, and participation in INTAiC offers access to shared threat assessments and collective response mechanisms for managing emerging AI cyber capabilities.
- ai security
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
Sophos analyzed its own endpoint data and identified that artificial intelligence (AI) coding agents including Claude Code, Cursor, and OpenAI Codex trigger detection rules designed to catch attackers. These agents perform benign activities like decrypting browser credentials and querying Windows credential stores, but the behaviors mimic intrusion tactics from a detection engine's perspective.
Why it matters: Security operations teams running endpoint detection and response (EDR) need to tune or suppress false positives from legitimate AI coding tools to avoid alert fatigue and maintain effective threat detection for actual attackers.
- ai security
Protecting Microsoft at AI speed: How SFI proactively hardens our cloud
Microsoft has built a multi-agent artificial intelligence (AI) system that proactively evaluates and hardens its cloud infrastructure against security vulnerabilities by analyzing code, configurations, identity settings, network topology, and runtime states. The system, part of the Secure Future Initiative, identifies composite vulnerabilities that emerge from the interplay of multiple components rather than isolated flaws, and compresses analysis that traditionally takes weeks into hours. This internal capability assesses services against Microsoft's stringent security requirements across identity, network, tenant isolation, engineering systems, and detection domains.
Why it matters: Cloud infrastructure operators and security teams need to understand that AI-powered vulnerability discovery now operates at expert level, requiring continuous proactive evaluation beyond traditional single-component security reviews to catch composite vulnerabilities that expose production services.
- threat intel
Taiwan charges two businessmen over alleged role in Chinese espionage campaign
Taiwan prosecutors charged two businessmen for allegedly operating a company that leased LINE messaging app accounts to Chinese intelligence operatives. The scheme provided unauthorized access to the messaging platform through legitimate business accounts, facilitating covert communications.
Why it matters: Organizations using LINE and practitioners in Taiwan face targeted espionage via compromised accounts; this demonstrates how commercial messaging platforms can be weaponized through account-leasing schemes that bypass security controls.
- threat intel
Entra passkey enrollment vishing targets Microsoft 365 users
A threat actor is targeting Microsoft 365 users with vishing (voice phishing) attacks that impersonate security personnel and request enrollment of a new Entra passkey. The campaign affects organizations across multiple sectors.
Why it matters: Microsoft 365 administrators and employees should be aware of this vishing technique targeting Entra ID, as successful passkey enrollment by attackers could enable unauthorized access to cloud infrastructure and business-critical data.
- threat intel
Vidar Infostealer Hammers SMBs via Malvertising Campaign
A financially motivated cybercriminal campaign distributes Vidar infostealer malware through malvertising and fake pirated software offers, combining data theft capabilities with cryptomining functionality. The operation targets small and medium-sized businesses with lures promoting cracked or pirated software. The dual-purpose attack seeks both immediate financial gain from mining and longer-term value from stolen credentials and sensitive data.
Why it matters: SMB security teams need to block malvertising and educate users that pirated software downloads carry embedded malware threats, as Vidar's infostealer component directly compromises credentials and business data while cryptominers degrade system performance.
- breaches incidents
Another massive data breach exposed millions of driver’s license numbers
A cyberattack on a major U.S. insurance company has exposed millions of driver's license numbers, marking the largest breach of such credentials recorded in 2026. The breach represents a significant loss of personally identifiable information at scale.
Why it matters: Drivers and customers of affected insurers face identity theft risk and must monitor for fraudulent use of their license numbers; security teams should assess whether their organization uses this insurer's services or handles similar data.
- breaches incidents
Patients Sue Healthcare Corporations Over Data Breaches, Sharing of Personal Information
Multiple class action lawsuits have been filed against large healthcare corporations for exposing or leaking patients' personally identifiable information and protected health information. The suits seek to hold healthcare companies accountable for data breaches, with cases filed in both state and federal courts.
Why it matters: Healthcare providers and their legal counsel face litigation risk from patient data breaches; practitioners should review incident response and data handling practices to identify and remediate similar exposure vectors.
- regulatory
Why Bangladesh’s new data protection law may fail to protect your data
Bangladesh's major retail chain Shwapno suffered a breach in August 2025 exposing personal data of 4 million customers, including names, phone numbers, and purchase histories. The company did not disclose the incident to affected customers for seven months, raising questions about the effectiveness of Bangladesh's data protection law in enforcing notification and transparency requirements.
Why it matters: Organizations operating in Bangladesh and customers whose personal data is subject to Bangladesh's jurisdiction need to understand the enforcement gaps in the new law, and practitioners must assess whether their data protection policies meet the actual disclosure standards being applied in the market.
- threat intel
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
Researchers have identified a new attack method called HalluSquatting that exploits the tendency of artificial intelligence (AI) coding assistants to fabricate package names. Attackers can predict these hallucinated names, register them as legitimate packages, and wait for the AI assistant to inadvertently install malicious code from those packages onto user systems. The attack leverages the gap between what AI models believe to exist and what is actually available in package repositories.
Why it matters: Organizations using AI coding assistants face supply chain risk if assistants auto-install hallucinated package names controlled by attackers; security teams should monitor developer tool outputs and consider restricting automatic package installation in AI assistant integrations.
- vulnerabilitiesCVE-2026-50746
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Ubiquiti released patches for multiple critical vulnerabilities across its UniFi product line, including Connect, Talk, Access, Protect, and OS platforms. The flaws enable privilege escalation and arbitrary command execution, with at least one vulnerability receiving a maximum CVSS severity score of 10.0.
Why it matters: Organizations deploying Ubiquiti UniFi infrastructure should prioritize patching immediately, as these critical flaws allow attackers to gain elevated access and execute commands on affected systems.
- regulatory
Former UK privacy chief preparing legal action against woman who reported him, minister says
The UK Secretary of State for Science, Innovation and Technology expressed strong disapproval of an independent investigation that found sexual harassment and bullying at the Information Commissioner's Office (ICO). The former privacy chief is reportedly preparing legal action against a woman who reported the allegations.
Why it matters: Practitioners who handle data privacy and regulatory compliance should monitor ICO leadership stability and potential operational changes, as the agency's credibility and internal governance directly affect how UK organizations navigate data protection obligations.
- vulnerabilitiesCVE-2026-55255
Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)
The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-55255 to its Known Exploited Vulnerabilities catalog on July 7, 2026, after attackers began exploiting the flaw in the wild. The vulnerability affects Langflow, an open-source visual framework for building artificial intelligence (AI) agents and workflows used by developers, enterprises, and service providers. Threat researchers at Sysdig observed active exploitation approximately two weeks before CISA's official listing.
Why it matters: Organizations and developers using Langflow for AI workflows face immediate credential harvesting risk from exploitation of CVE-2026-55255 and should prioritize patching or disabling affected instances.
- ai security
3 Ways AI Powers Service Desk Attacks and How to Prevent Them
Specops Software outlines how artificial intelligence (AI) is enhancing service desk impersonation attacks by making them more convincing, personalized, and scalable. The article discusses practical defenses for organizations, including improvements to onboarding and identity verification processes.
Why it matters: Security teams managing service desk operations need to understand AI-driven social engineering tactics targeting their helpdesk and implement stronger identity verification controls to prevent unauthorized account access and lateral movement.
- ai security
GhostApproval: A Trust Boundary Gap in AI Coding Assistants
Researchers identified GhostApproval, a trust boundary gap in artificial intelligence (AI) coding assistants that exploits weaknesses in human-in-the-loop safety models. The vulnerability represents a category-level issue affecting how these tools validate and approve code suggestions. The finding exposes a gap between the intended safety architecture and actual threat exposure in widely deployed AI coding systems.
Why it matters: Development teams using AI coding assistants face the risk of accepting malicious or insecure code suggestions that bypass approval workflows, requiring immediate review of how these tools integrate into code review processes.
- cloud saas
Censys Internet Map links real-time DNS data to internet infrastructure
Censys has expanded its Internet Map platform to integrate real-time DNS visibility, enabling security teams to pivot between domains, DNS records, and infrastructure details in a single interface. The addition consolidates workflows that previously required multiple datasets and tools into one cohesive platform.
Why it matters: Security teams conducting asset discovery, reconnaissance, and infrastructure mapping can streamline investigations by reducing context switching and tool sprawl during incident response and threat hunting.
- identity access
Blackpoint AI SOC Agent autonomously contains identity-based attacks
Blackpoint Cyber released an autonomous identity threat detection and response (ITDR) capability that uses artificial intelligence (AI) and human collaboration to contain credential-based attacks against Microsoft 365 and Google Workspace. The system achieves average containment times under two minutes, with some incidents stopped in as little as 21 seconds.
Why it matters: Organizations using Microsoft 365 or Google Workspace need to evaluate autonomous AI-driven response tools to reduce the window of exposure for identity-based attacks and minimize manual intervention delays.
- ai security
First Recon AI Security Runtime helps enterprises govern AI with audit-ready evidence
First Recon artificial intelligence (AI) announced general availability of its AI Security Runtime, a platform that inspects every interaction involving artificial intelligence (AI) models, applies security policies before data reaches those models, and records decisions as audit-ready evidence. The tool enables enterprises to adopt AI while maintaining governance and compliance controls across human-to-model, agent-to-tool, and agent-to-agent interactions.
Why it matters: Security and compliance teams deploying AI across their organizations need runtime controls and audit trails to manage risk and demonstrate governance to regulators and auditors.
- threat intel
Webinar Today: Why Email Security Keeps Failing
A webinar is being held to discuss limitations of email-layer security defenses against modern phishing threats. The session explores why email security alone is insufficient for protecting against contemporary attack methods.
Why it matters: Security practitioners responsible for email security and phishing defense should attend to understand gaps in their current defenses and consider layered protection strategies.
- cloud saas
FalconStor Cloud Clean Room enables validated recovery without dedicated infrastructure
FalconStor released Cloud Clean Room, an on-demand infrastructure platform for validated recovery testing within a secure enclave. The service resets to a known state for each test to prevent carryover of issues from previous exercises, leveraging FalconStor's zero trust secure enclave technology.
Why it matters: Backup and disaster recovery teams can now test recovery procedures without procuring and maintaining dedicated infrastructure, reducing operational overhead and improving confidence in recovery processes.
- government policy
EU unveils cyber plan to reduce reliance on foreign AI systems
The European Commission adopted a communication on July 7 outlining a three-pillar strategy to advance EU cybersecurity through artificial intelligence. The approach focuses on making frontier AI safe and accessible for European cybersecurity applications, strengthening the EU's cyber ecosystem, and developing Europe's own AI capabilities to reduce dependence on foreign systems.
Why it matters: Security practitioners and EU-based organizations should monitor this policy direction as it may influence funding, tooling, and regulatory expectations around domestically developed AI solutions for defense operations.
- threat intel
Security Teams Are Ready To Become More Preemptive. What’s Holding Them Back?
Rapid7's Global Security Summit survey reveals that security teams want to shift toward proactive threat prevention but face structural obstacles. Most organizations operate in a hybrid internal and managed detection and response (MDR) model, with two-thirds reporting only partial integration across their security tools and 10% describing themselves as highly proactive. Artificial intelligence (AI) adoption remains in early stages, with security leaders prioritizing trust and transparency as they evaluate AI for triage and alert enrichment.
Why it matters: Security practitioners should recognize that partial tool integration and reactive postures remain industry norms, making the business case for consolidation and automation stronger; investment in AI governance and transparency mechanisms will differentiate organizations moving toward operational maturity.
- threat intel
New Ghost Phishing Wave Is Breaking Traditional Email Security
A new phishing campaign called EvilTokens uses encrypted payloads that remain hidden from email security scanning until they decrypt in the victim's browser, bypassing traditional URL-based detection. This technique targets businesses in the US and Europe, potentially exposing Microsoft 365 accounts and sensitive data to compromise.
Why it matters: Email security teams and Microsoft 365 defenders need to evaluate detection gaps for encrypted phishing payloads, as traditional gateway and URL filtering may fail to catch these attacks before they reach end users.
- threat intel
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
A threat actor tracked as REF6045 is targeting Mexican banking customers, fintech users, and cryptocurrency exchange clients using ClickFix lures that impersonate CAPTCHA verification pages. The attack chain tricks victims into executing malicious PowerShell commands that install a banking malware toolkit called SCMBANKER. This represents an emerging fraud operation against financial services and payment infrastructure in Mexico.
Why it matters: Financial services organizations, fintech firms, and cryptocurrency exchanges operating in Mexico need to alert customers about fake CAPTCHA lures and implement endpoint detection for suspicious PowerShell execution, as compromised banking credentials can lead to unauthorized fund transfers and account takeovers.
- cloud saas
DNSFilter makes its DNS threat protection available to OEM partners
DNSFilter has introduced an Original Equipment Manufacturing (OEM) program that allows ISPs, cybersecurity firms, device makers, and consumer app developers to embed its Domain Name System (DNS) threat protection and related services into their own platforms. Partners can choose either the Protective DNS offering for filtering and threat blocking, or the Guardian Firewall and Virtual Private Network (VPN) services for full‑device traffic encryption and privacy, or they can bundle both. The program provides technical documentation, APIs, and branding options to facilitate integration.
Why it matters: ISPs, cybersecurity firms, device makers, and consumer app developers can now embed Domain Name System (DNS) threat filtering and Virtual Private Network (VPN) services into their offerings, providing a turnkey security layer they can sell to end users.
- industry
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup called IRIS C2 that claims to acquire zero-day exploits and offer million-dollar payouts is operated by Jack Burkman and Jacob Wohl, two convicted felons with a documented history of creating fake intelligence companies and spreading disinformation. The pair have faced multiple criminal convictions and civil judgments related to robocall schemes, telecommunications fraud, and civil rights violations. IRIS C2 is registered as a federal contractor but does not appear to be executing any direct government contracts.
Why it matters: Security researchers and potential employees should exercise extreme caution before engaging with IRIS C2, given the operators' criminal history and pattern of deception; organizations and government agencies should scrutinize any claims or contracts associated with this entity.
- ai security
Attestiv DeepScan combines AI and forensic analysis for file validation
Attestiv launched DeepScan, a platform that combines artificial intelligence (AI) and forensic analysis to validate submitted files including photos, documents, audio, and video before they influence business decisions. The platform shifts focus from detecting manipulated media in isolation to assessing whether files are trustworthy within specific business workflows. Deepfake detection is now integrated as part of the broader file validation process.
Why it matters: Organizations handling customer-submitted files face risks from deepfakes and manipulated media that could compromise decision-making; this tool provides a way to automatically validate file authenticity before operational impact.
- cloud saas
Wiz ASM for any environment, any risk, everywhere
Wiz announced new features for its Attack Surface Management (ASM) platform, including auto-reconnaissance capabilities, deep internal context analysis, and a Red Agent tool designed to identify risks across different environments.
Why it matters: Security teams evaluating ASM solutions should understand the expanded capabilities available for discovering and managing risks in cloud and on-premises infrastructure.
- industry
DuckDuckGo browser now blocks YouTube video ads
DuckDuckGo has released an update to its browser that blocks most YouTube video advertisements, including pre-roll and mid-roll ads.
Why it matters: End users concerned with ad blocking and privacy gain a built-in feature, but website administrators and content creators relying on YouTube revenue should monitor adoption of competing browsers and ad-blocking capabilities.
- vulnerabilities
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
Researchers discovered that signed Git commits can be rewritten to produce different hashes while maintaining valid signatures that GitHub still verifies as legitimate. An attacker without the signing key can create a duplicate commit with identical files, author, and date information, yet a different hash value, and GitHub's verification will still pass.
Why it matters: Development teams relying on commit verification as a supply chain control are at risk of accepting malicious code that appears legitimately signed; practitioners should review their Git security practices and commit verification workflows to account for this hash collision issue.
- identity access
The Verification Step Is the New ATO Battleground in 2026
Account takeover attacks are shifting focus from initial credential compromise to the verification step as passkeys and other authentication hardening become more widespread. Attackers are moving away from traditional credential stuffing since the initial login barrier has strengthened, making post-authentication compromise a new priority for threat actors.
Why it matters: Security practitioners need to reassess and strengthen verification and session management controls, as attackers will increasingly target second-factor authentication and post-login verification steps rather than weak initial passwords.
- breaches incidents
Accenture acknowledges security incident following 35GB data theft claim
Accenture confirmed a security incident after a threat actor known as '888' claimed on a cybercrime forum to have stolen over 35 gigabytes of data in July 2026. The alleged exfiltrated materials include source code, cryptographic keys, cloud access tokens, and configuration files. The full scope of the breach and impact remain unclear.
Why it matters: Accenture customers and partners using the company's code, cloud infrastructure, or security credentials should assess exposure to stolen access keys and source code that could enable further compromise or authentication bypass.
- ai security
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
Researchers found that GitHub Copilot and other large language models refuse to generate harmful code when asked directly in chat, but will produce the same functionality when the request is broken into small, innocuous-looking steps within a code editor. The study examined Claude from Anthropic and Gemini from Google alongside Copilot, demonstrating a significant gap between the models' safeguards in different contexts.
Why it matters: Development teams using artificial intelligence (AI) coding assistants should recognize that refusal mechanisms can be circumvented through prompt fragmentation, requiring additional code review processes and awareness when integrating AI-generated suggestions into production systems.
- ransomware
Cybersecurity and the Gap Between Skill and Ability
Five Eyes national security agencies warned of growing cyber risks from artificial intelligence models capable of autonomous system attacks and network compromise. The article argues that AI has widened the gap between skill and ability, enabling individuals without deep technical expertise to conduct sophisticated cyberattacks similar to how pre-written hacking tools once democratized attack capabilities. The author contends that guardrails and monitoring of AI systems will prove insufficient as open-source models proliferate beyond corporate control.
Why it matters: Security practitioners need to recognize that AI-assisted attacks will increasingly come from less technically skilled threat actors, requiring defense strategies that account for both autonomous AI capabilities and the expanded attacker pool this technology enables.
- vulnerabilities
CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
CISA has added four newly exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: critical flaws in Adobe ColdFusion and Langflow, plus two Joomla extension vulnerabilities. Federal agencies have until July 10 to apply patches for these active threats.
Why it matters: Federal agencies and contractors must prioritize patching these four vulnerabilities by the July 10 deadline to comply with CISA directives; organizations running ColdFusion, Langflow, or affected Joomla extensions should treat these as urgent given active exploitation.
- breaches incidents
OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear
Scammers are exploiting compromised government websites to host advertisements for stolen OnlyFans content. Copyright complaints filed by adult content creators against these malicious ads are inadvertently causing the hijacked government pages to be removed from search results and taken offline.
Why it matters: Government agencies and adult creators should monitor for unauthorized use of their assets; security practitioners need to prioritize defense and recovery of government infrastructure and help organizations understand how complaint mechanisms can yield unintended takedown effects.
- ot ics
What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out
Insurers conducted a classified tabletop exercise simulating a large-scale cyberattack on US water infrastructure by the Volt Typhoon threat group, modeling cascading failures such as ruptured pipes and hospital evacuations. The exercise revealed significant gaps in preparedness and response coordination for such a critical infrastructure breach.
Why it matters: Water utilities, hospitals, insurers, and government agencies need to assess their resilience to nation-state threats against essential services; this exercise demonstrates the real-world consequences of OT (operational technology) compromise and underscores urgent mitigation priorities.
- vulnerabilities
CISA orders feds to prioritize patching Langflow auth bypass flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a directive requiring federal agencies to patch an actively exploited authentication bypass vulnerability in Langflow, a visual framework for constructing artificial intelligence (AI) agents. The deadline for remediation was set for Friday of the same week.
Why it matters: Federal agencies and organizations using Langflow must patch this flaw immediately, as CISA has confirmed active exploitation and enforcement of the deadline.
- ai security
Crusoe brings serverless fine-tuning to AI model development
Crusoe announced serverless fine‑tuning and self‑serve deployments in its Intelligence Foundry platform for Crusoe Cloud. The offering lets data scientists and machine learning (ML) engineers move proprietary data to production‑ready artificial intelligence (AI) models without managing the underlying infrastructure.
Why it matters: Data scientists and machine learning engineers can now fine-tune and deploy open-source AI models on Crusoe's serverless platform, removing infrastructure management overhead.
- cloud saas
Automox MCP Server adds visual reviews and AI-driven patch policy creation
Automox released MCP Server 2.2, which introduces interactive visual review surfaces, automated Patch by Severity policy generation, and live capability discovery for its agent interface. The update expands beyond natural-language controls to provide IT teams with contextual approval and execution capabilities for endpoint operations.
Why it matters: Patch and system administrators using Automox can now create patch policies faster and review agent actions visually before execution, reducing manual policy overhead and approval friction.
- ai security
Thousands of malicious AI skills found capable of stealing data, running malware
A review of nearly 900,000 artificial intelligence (AI) skills identified more than 25,000 suspicious skills capable of stealing data, executing malware, or manipulating agent behavior, according to the H1 2026 ESET Threat Report. Malicious skills exploit the broad capabilities AI agents use to browse the web, deploy external tools, and run commands on behalf of users. The discovery expands the understood attack surface for AI-driven systems.
Why it matters: Organizations deploying AI agents or allowing users to install third-party skills face data theft and malware execution risks; security teams should audit and control skill installation policies.
- threat intel
Helix, a New Name in the Data Extortion Ecosystem?
ReliaQuest researchers identified a previously unreported data extortion group called Helix that uses vishing, device code phishing, and automated SharePoint exfiltration to target multiple organizations. The group's tactics and infrastructure show strong similarities to the defunct BlackFile group and ShinyHunters, suggesting it either emerged from or operates within the same ecosystem. Defenders can significantly reduce risk by disabling device code authentication, restricting SaaS applications to managed endpoints, and blocking newly registered domains.
Why it matters: Organizations face active SharePoint-targeting extortion campaigns using identity-based techniques that bypass conditional access; defenders should prioritize device code authentication disablement and managed endpoint controls to close the entry points Helix exploits.
- cloud saas
ScienceLogic adds geographic service visibility to Skylar One
ScienceLogic released the Kyoto update for its Skylar One observability platform, adding geographic service visibility, enhanced relationship mapping, and location management capabilities. The update targets organizations operating hybrid infrastructure and cloud environments seeking improved visibility into service issues and platform resilience.
Why it matters: IT operations teams managing hybrid and cloud infrastructure may benefit from these observability enhancements if they currently lack geographic context for troubleshooting service outages or managing distributed locations.
- industry
Codenotary launches AI security platform that learns from AI agent behavior
Codenotary released AgentMon 3, an artificial intelligence (AI) security platform that updates its policies by learning from AI agent behavior, workflow patterns, and emerging threats. The platform is now available through AWS Marketplace, allowing organizations already using Amazon Web Services to deploy it with fewer steps. These changes aim to provide continuous, behavior‑based protection for enterprise AI systems.
Why it matters: Enterprises deploying AI agents, particularly those on AWS, should evaluate AgentMon 3 from AWS Marketplace to gain adaptive, behavior‑based security that evolves with agent activity and emerging threats.
- vulnerabilities
Ubiquiti warns of new max severity UniFi OS vulnerability
Ubiquiti released security updates addressing seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw exploitable through command injection attacks.
Why it matters: Organizations running UniFi OS should apply these patches immediately to prevent remote code execution through the maximum-severity vulnerability.
- research
My Stack Simulator
A security researcher has created a stack simulator tool to help students visualize how the stack memory region works during program execution, particularly for malware analysis students learning assembly language. The simulator allows users to select architecture, choose predefined instruction sets, step through code execution, and observe real-time changes to the stack and registers similar to a debugger interface.
Why it matters: Malware analysts and reverse engineers benefit from this educational tool to build foundational understanding of stack behavior, which is essential for identifying stack-based exploits and understanding how attackers manipulate program execution flow.
- ai security
State IDs for AI Agents: Will Estonia Set a Precedent?
Estonia is exploring the creation of state-issued digital identities for artificial intelligence (AI) agents to enable their use in government services and interactions. The initiative positions Estonia as a potential early adopter in establishing authentication standards for AI systems in the public sector.
Why it matters: Government security and identity practitioners need to monitor AI authentication frameworks, as state-issued digital identities for agents could set precedents for how enterprises and other jurisdictions manage AI system identity, access, and accountability in sensitive environments.
- ai security
Claude Cowork turns your phone into a remote control for AI work
Anthropic launched Claude Cowork, a beta feature for Max subscribers that deploys an artificial intelligence (AI) agent to handle multi-step tasks across mobile and web platforms. Users describe objectives, and the agent plans work, invokes necessary tools, and generates outputs including documents, spreadsheets, presentations, and reports. Tasks persist in background execution even when devices are offline or closed.
Why it matters: Organizations and Max subscribers evaluating AI (agent) tools for workflow automation should assess whether background task execution and offline scheduling capabilities reduce operational friction in their environments.
- ai security
Hackers can use 9 of the most popular AI tools to assemble massive botnets
Researchers demonstrated that prompt injection attacks can be scaled across nine popular artificial intelligence tools to assemble large-scale botnets, moving beyond individual targeting. The attack exploits the inherent inability of large language models to distinguish between legitimate user instructions and malicious commands embedded in emails, source code, and other third-party content. Current mitigation approaches rely on guardrails rather than addressing the fundamental boundary problem between trusted and untrusted data sources.
Why it matters: Organizations using popular AI tools for email processing, content analysis, or automated workflows face risk of mass exploitation through prompt injection if adversaries gain the ability to inject malicious commands at scale; practitioners should evaluate current AI tool deployments for untrusted input handling and implement strict input validation controls.
- vulnerabilitiesCVE-2026-43499
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Researchers at Nebula Security disclosed GhostLock (CVE-2026-43499), a Linux kernel vulnerability present in the codebase since 2011 that affects most mainstream distributions. The flaw allows any logged-in user to gain root privileges without requiring special permissions, unusual configurations, or network access.
Why it matters: System administrators and Linux users need to prioritize patching immediately, as any authenticated local user can escalate to root on vulnerable systems, exposing all data and systems to compromise.
- ot ics
Orbia CISO Miranda Ritchie on building security into sustainable infrastructure
Miranda Ritchie, CISO at Orbia, discusses integrating security into industrial systems that manage water, chemical, and manufacturing processes. She addresses the unique risks of operational technology (OT) environments, including geographically dispersed sites and legacy hardware, and advocates for embedding security teams early in project development and adopting zero-trust principles aligned with safety culture.
Why it matters: OT and critical infrastructure practitioners need guidance on balancing security with safety in systems where cyber incidents can cause physical harm, equipment damage, or environmental impact.
- regulatory
Risky Bulletin: All new cars to include a camera aimed at the driver's face
The European Union has mandated that all new cars include an infrared camera monitoring the driver's face to detect distracted driving, with the same requirement set to take effect in the US next year. The camera tracks head position and eye movements to alert drivers when their attention drifts from the road. Privacy advocates have raised concerns about the continuous facial surveillance capability.
Why it matters: Vehicle manufacturers and privacy-conscious drivers need to understand the compliance requirements and implications of mandatory in-cabin monitoring across new vehicles in major markets.
- research
20 open-source cybersecurity tools to keep your team ready for anything
A roundup article surveys 20 recent open-source security tools covering vulnerability research, application security testing, container security, endpoint protection, artificial intelligence (AI) security, and penetration testing. The tools address emerging concerns around securing AI systems, including detection of exposed AI endpoints and infrastructure scanning.
Why it matters: Security teams evaluating open-source alternatives for testing and defense can use this guide to identify tools relevant to their CI/CD pipelines, AI deployments, and threat scenarios.
- ai security
macOS is becoming a proving ground for AI agents
macOS is emerging as a test environment for autonomous artificial intelligence (AI) agents that perform multi-application tasks without human intervention. These agents execute routine workflows across system terminals and web browsers, automating workflows that would typically require manual user effort.
Why it matters: Security teams must evaluate risks from AI agents running unsupervised on macOS endpoints, including privilege escalation, data exfiltration, and lateral movement potential if agent behavior becomes compromised or misaligned.
- research
How to implement a continuous offensive security testing program
Continuous offensive security testing addresses the limitation of point-in-time penetration tests, which become outdated as environments change and controls drift. The article discusses the challenge of deciding how to remediate findings and maintaining confidence in those decisions over time as security postures evolve.
Why it matters: Security teams need to understand how to implement ongoing testing programs to catch exposures that emerge between traditional assessments and maintain current visibility into their network's actual security state.
- ai security
OpenAI and Anthropic are pulling in different directions
OpenAI and Anthropic are pursuing divergent strategies for deploying artificial intelligence (AI) agents that handle operational decisions, plan tasks, and retain memory over time. AI agent behavior can drift across weeks and months, creating security gaps that existing monitoring tools may not detect. Job postings at each company reveal their different budget priorities and technical directions in this area.
Why it matters: Security teams need to understand how AI agents behave over time in their infrastructure; behavioral drift in autonomous systems can bypass traditional detection and create exploitable gaps that require new monitoring approaches.
- ai security
The Threat Isn’t the Frontier Model
Analysts note that while frontier artificial intelligence (AI) models pose limited immediate offensive capability, adversaries are increasingly able to run effective open‑source models on modest hardware after quantization advances. They advise Chief Information Security Officers (CISOs) to start constructing and testing defensive AI agents now to prepare for the anticipated rise of machine‑speed attacks.
Why it matters: CISOs and security teams face imminent AI‑enabled adversary activity and should begin building defensive AI agents today.
- breaches incidents
Washington Dept. of Social and Health Services announces massive data breach
Washington State's Department of Social and Health Services discovered an unauthorized data access incident in March involving a former employee who accessed personal information of approximately 8,600 individuals. The breach was identified through an internal investigation, and the agency is issuing notice to affected parties.
Why it matters: Individuals in Washington State should monitor for identity theft and contact the agency for details on what personal data was exposed and what mitigation steps are available.
- threat intel
DeepLoad Malware Pairs ClickFix Delivery with AI-Generated Evasion
DeepLoad malware reaches enterprises through ClickFix social engineering, where a single user‑executed PowerShell command downloads and runs a fileless loader that hides code in thousands of dummy variables and injects into the Windows lock screen process. The loader establishes persistence via a scheduled task and WMI event subscriptions, steals credentials in real time, can reinfect hosts three days after apparent cleanup, and spreads to attached USB drives.
Why it matters: Enterprise security teams are affected because DeepLoad steals credentials in real time and can reinfect systems three days after cleanup, requiring them to enable PowerShell Script Block Logging, audit WMI subscriptions, and rotate credentials from the infection window.
- threat intel
No Safe Distance: The Business Impact of Recent Global Developments
The US-Israel-Iran conflict has expanded beyond military operations into commercial infrastructure, with Iranian state actors and hacktivist groups targeting cloud data centers, medical technology firms, point-of-sale systems, and other private sector assets. Organizations face pressure not only from direct intrusions but also from supply chain disruptions, distributed denial-of-service attacks, and reputational damage. Companies without direct involvement in the conflict may still face targeting due to business relationships, supply chain roles, or perceived ties to involved countries.
Why it matters: All organizations relying on cloud platforms, supply chains, or internet-connected infrastructure need to assess their exposure to geopolitical conflict spillover by mapping supply chain risks, hardening privileged access controls, auditing connected devices, and maintaining tested offline backups.
- threat intel
ShinyHunters Fast-Tracks SaaS Access with Subdomain Impersonation
ShinyHunters has shifted from registering lookalike domains to using subdomain impersonation, placing brand names in subdomains of generic SSO or login-themed domains to evade detection. The group pairs these lures with mobile-first adversary-in-the-middle phishing, phone-guided social engineering, and reused SaaS customer data to rapidly compromise identity systems and access across enterprise applications without deploying malware. This technique enables attackers to pivot from a single valid SSO session or help desk reset to broad access to email, files, human resources, and customer relationship management systems.
Why it matters: SaaS administrators and identity teams must prioritize phishing-resistant multi-factor authentication and rapid session containment, as this attack path bypasses traditional domain monitoring and can compromise multiple applications through a single credential reset.
- ransomwareCVE-2026-23760CVE-2026-24423
Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware
ReliaQuest identified exploitation of CVE-2026-23760, a critical SmarterMail vulnerability, by the China-based threat actor Storm-2603 to bypass authentication and stage Warlock ransomware. The group abuses the software's Volume Mount feature for system control, then deploys Velociraptor, a legitimate forensic tool, to maintain persistence and prepare for ransomware deployment. The activity occurs alongside a separate wave of probes for CVE-2026-24423, indicating multiple threat vectors targeting internet-facing mail servers.
Why it matters: Organizations running SmarterMail must immediately upgrade to Build 9511 or later and implement network isolation around mail servers to block the attack chain from initial access through ransomware staging, as Storm-2603 is actively exploiting these vulnerabilities in production environments.
- ransomware
New Campaign Uses Screensavers for RMM-Based Persistence
ReliaQuest identified a spearphishing campaign delivering Windows screensaver (.scr) files that silently install legitimate remote monitoring and management (RMM) tools, granting attackers persistent interactive access. The attack uses business-themed email lures to trick users into downloading and executing .scr files from cloud storage platforms like GoFile, leveraging the trusted services and overlooked screensaver executable type to evade detection. The technique is repeatable, scalable, and enables attackers to escalate to credential theft, data exfiltration, and ransomware deployment.
Why it matters: Security teams need to immediately restrict .scr file execution from user-writable locations and implement approved-RMM allowlists with alerting, as this campaign exploits the conflation of legitimate remote-support software with attacker persistence infrastructure in ways that blend into normal IT operations.
- threat intel
Open-Source Python Script Drives Social Media Phishing Campaign
Attackers are conducting phishing campaigns via LinkedIn and other social media platforms, delivering malicious WinRAR archives that use DLL sideloading combined with an open-source Python pen-testing script to deploy remote access trojans. The campaign exploits social media's professional credibility and targets high-value individuals like executives and IT administrators with role-specific file names to increase success rates. Once executed, the malware can escalate privileges, move laterally across networks, and exfiltrate data.
Why it matters: Security teams and executives need to recognize social media, especially LinkedIn, as a primary phishing vector that many organizations overlook; implement social media-specific security awareness training and monitor for weaponized open-source tools being delivered through trusted platforms on corporate devices.
- ransomware
Threat Spotlight: How Automation, Customization, and Tooling Signal Next Ransomware Front Runners
Analysts note that ransomware-as-a-service groups relying on automation, customization, and advanced tooling attract skilled affiliates and achieve faster breakout times, with 80% of surveyed groups incorporating automation and average breakout time falling to 18 minutes. The report identifies emerging groups “The Gentlemen” and “DragonForce” as likely next-generation threats and recommends that defenders counter these tactics through automated responses, network segmentation, and layered security.
Why it matters: Security teams facing ransomware should expect faster attacks from groups using automation and should prioritize automated detection, network segmentation, and layered defenses.